Our call: Is anime.expeditions.v0.6.zip safe?Suspicious
This archive contains an executable exhibiting process injection and automated network communication, which are behaviors commonly associated with trojan-style downloaders despite limited detection by our antivirus network.
- 1 high-confidence signature or behavior rule matched this file.Derived · Signature and behavior rules
- 1 of 74 antivirus engines flagged the file, including Zillya.Observed · Antivirus analysis
- The hash has been submitted 50 times from 42 sources.Derived · Saved report facts
560bdf7dea29ec23ae…062e2ebceeRecommended next actions
Before opening or extracting
Do not open or extract it until the source can be verified independently.
If you already opened or extracted it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the original trusted source and verify its exact hash when possible.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete1 of 74 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial1 of 3 contacted hosts were cross-checked; coverage is incomplete.
YARA
Complete2 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
anime.expeditions.v0.6.zip
560bdf7dea29ec23ae4c16ce44802af7e979efe4eb595706339805062e2ebcee
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\AppData\Local\Temp\AnimeExpeditionsMacro.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\system32\cmd.exe /c curl.exe -s --max-time 10 "https://as-keys.hypermonarch0.workers.dev/ea?product=anime_expeditions" > "C:\Users\<USER>\AppData\Local\Temp\gm_curl_55656.txt"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
gm_curl_55656.txt
C:\Users\<USER>\AppData\Local\Temp\gm_curl_55656.txt
04Isolated runtime analysis - Written fileObserved
settings.ini
C:\Users\<USER>\AppData\Local\Temp\configs\settings.ini
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
172.67.142.16
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostObserved
162.159.36.2
Contact observed during runtime.
07Isolated runtime analysis - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
1 of 74 antivirus engines flagged the file, including Zillya.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has been submitted 50 times from 42 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: anime.expeditions.v0.6.zip — 560bdf7dea29ec23ae4c16ce44802af7e979efe4eb595706339805062e2ebcee
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\AppData\Local\Temp\AnimeExpeditionsMacro.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\system32\cmd.exe /c curl.exe -s --max-time 10 "https://as-keys.hypermonarch0.workers.dev/ea?product=anime_expeditions" > "C:\Users\<USER>\AppData\Local\Temp\gm_curl_55656.txt"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: gm_curl_55656.txt — C:\Users\<USER>\AppData\Local\Temp\gm_curl_55656.txt
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: settings.ini — C:\Users\<USER>\AppData\Local\Temp\configs\settings.ini
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: 172.67.142.16 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: 162.159.36.2 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The file exhibits suspicious runtime behaviors, including process injection and automated network requests to external infrastructure. While only one engine currently flags the sample, the combination of these techniques and the presence of input-simulation mutexes suggests potential malicious intent.
Our analysis identified offensive MITRE techniques, specifically process injection and defense impairment, during the sandbox execution. The sample performs automated network requests using curl to external infrastructure, which is a common pattern for malicious downloaders. Although the detection rate across our 74 engines is low, the observed behavior is inconsistent with standard, benign software. We recommend treating this file with caution due to these indicators of automated, potentially unauthorized activity.
What We Detected
The file is a ZIP archive containing an executable that triggers high-severity heuristics related to process injection (MITRE T1055) and defense impairment (MITRE T1562.001). While only one engine in our network currently identifies this as a trojan, the runtime behavior is highly atypical for legitimate applications.
Threat Behavior
During execution, the sample creates mutexes associated with automated input simulation ('AHK Keybd', 'AHK Mouse') and performs multiple network requests to external infrastructure via curl. These actions, combined with the creation of various log and configuration files in the temporary directory, are consistent with automated downloader or macro-based malware.
What To Do Now
Do not execute this file. If you have already run it, we recommend performing a full system scan with your endpoint protection software and reviewing your system for any unauthorized persistence mechanisms or unexpected network connections.
Where this verdict could be wrong2 caveats
- The vast majority of engines (73/74) did not flag the file, which could indicate the detection is a false positive or that the sample is highly targeted.
- No malicious children were identified among the 10 inspected dropped files, suggesting the primary payload may not have fully executed or is currently dormant.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 73/74 engines did not flag the file as malicious
- No malicious children identified in sandbox analysis
- MITRE T1055 (Process Injection)
- MITRE T1562.001 (Impair Defenses)
- Automated network communication to external IP addresses
- Creation of input-simulation mutexes
- Low engine detection rate may indicate a new or obfuscated threat
Do not execute this file. If you have already run it, perform a full system scan and monitor for suspicious network activity.
Behavior
Plain-English impact first, then the observed runtime evidence.
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Attempted to impair or bypass security controls.
Moderate concern: Runs hidden system commands (script or shell).
Moderate concern: Removed execution artefacts or logs, which can conceal activity.
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Moderate concern: Checked the environment for virtualisation or analysis tools.
Note: Reads your Windows user-account details.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 172.67.142.16
- 162.159.36.2
- https://as-keys.hypermonarch0.workers.dev/ea?product=anime_expeditions
- https://as-keys.hypermonarch0.workers.dev/verify
- C:\Users\<USER>\AppData\Local\Temp\gm_curl_55656.txt
- C:\Users\<USER>\AppData\Local\Temp\configs\settings.ini
- C:\Users\<USER>\AppData\Local\Temp\debug.log
- C:\Users\<USER>\AppData\Local\Temp\gm_curl_60671.txt
- C:\Users\<USER>\AppData\Local\Temp\gm_curl_68468.txt
- C:\Users\<USER>\AppData\Local\Temp\gm_curl_60671.txt
- C:\Users\<USER>\AppData\Local\Temp\gm_curl_68468.txt
- C:\Users\<USER>\AppData\Local\Temp\gm_curl_226359.txt
- C:\Users\<USER>\AppData\Local\Temp\gm_curl_226531.txt
- AHK Keybd
- AHK Mouse
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- f9b2f82da0876248edd3…dc3a89Never scannednever seen before
- dc127fa275da62e2cce6…db2250Never scannednever seen before
- 0ab34428cc7e294f63bf…ad3914Never scannednever seen before
- 290278dd12c152f0ce70…d3e816Never scannednever seen before
- c04f99dee1f3b85da672…232480Never scannednever seen before
- 0fa416eda7aa96281a67…091cb5Never scannednever seen before
- 3abc9bcb33d83a2d0a5d…391328Never scannednever seen before
- 5b216969401607b86163…864c13Never scannednever seen before
- a4fb0330fa19e94f9380…4e8f89Never scannednever seen before
- 50e48ba235e5029f845b…72ee93Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Detection sources at a glance
Category: generic-trojan
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
Evidence"C:\Users\<USER>\AppData\Local\Temp\AnimeExpeditionsMacro.exe"The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence172.67.142.16 · 162.159.36.2
1 of 74 engines flagged this file
View all 74 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- anime.expeditions.v0.6.zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 30.5 MB
- Last analyzed
- Jul 28, 2026, 11:31 PM UTC
560bdf7dea29ec23ae4c16ce44802af7e979efe4eb595706339805062e2ebceeSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
Don't open or extract it unless you're certain it came from a source you trust.
Check where you got it — an unexpected attachment or a random download link is a red flag.
If its origin cannot be confirmed, delete this archive and use a fresh copy from a trusted source. Get a fresh copy from the original trusted source and verify its exact hash when possible.
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.